image
image

Go Back   macosx.com > Content & Information > Apple News, Rumors & Discussion

Reply
 
Thread Tools
  #1  
Old March 1st, 2006, 05:17 PM
ElDiabloConCaca's Avatar
U.S.D.A. Prime
 
Join Date: Aug 2001
Location: San Antonio, Texas
Posts: 10,672
Thanks: 3
Thanked 160 Times in 148 Posts
ElDiabloConCaca is a jewel in the roughElDiabloConCaca is a jewel in the roughElDiabloConCaca is a jewel in the rough
New Security Update addresses "safe file" issue...

Get it while it's hot in Software Update (or download it manually, but what fun is that?).

http://docs.info.apple.com/article.html?artnum=303382

Now all those people bitching about how insecure Mac OS X is can shut their mouths. Those "proofs of concept" existed for what -- barely a week? -- and now Apple has patched it.

Dearest Crackers: next time be a little more creative with your exploits. Copying and pasting a JPEG icon on a UNIX executable has got to be the most juvenile attempt at an exploitation. Why don't y'all learn to REALLY write code instead of being crappy little script kiddies?

Go spread FUD somewhere else and just let us Mac users enjoy our Macs.
__________________
Power Macintosh G4/500MHz "Yikes!" 10.4.11 Server • 1024MB • 3 x 120GB + 320GB • DVR-111D
MacBook 2.0GHz Core 2 Duo - White 10.5.6 • 2048MB • 80GB • CD-RW/DVD-ROM
iPhone 3G 8GB • iPod Photo 60GB • iPod nano 1GB • AT&T DSL 6Mb/768k
http://www.jeffhoppe.com
Reply With Quote
  #2  
Old March 1st, 2006, 06:17 PM
Satcomer's Avatar
In Geostationary Orbit
 
Join Date: Jul 2002
Location: Northern Virginia
Posts: 5,577
Thanks: 5
Thanked 61 Times in 59 Posts
Satcomer is a jewel in the roughSatcomer is a jewel in the roughSatcomer is a jewel in the roughSatcomer is a jewel in the rough
Does it really help with the shell scripts from a browser?
__________________
PowerMac G5 Dual 1.8(Rev A.), , 7 Gig RAM, Pioneer DVR-110, ATI X800XT, OS X 10.4.11 & 10.5.5, 23'' HD LCD
Mac Book Pro Core 2 Duo 2.16Mhz, SuperDrive, ATI X1600, 2GB RAM, OS X 10.5.5
1TB Time Capsule
5g iPod 30Gig White
Reply With Quote
  #3  
Old March 1st, 2006, 06:35 PM
fryke's Avatar
Super Moderator
 
Join Date: Sep 2000
Location: macosx.com
Posts: 13,498
Thanks: 2
Thanked 32 Times in 30 Posts
fryke has a spectacular aura aboutfryke has a spectacular aura about
ElDiablo: It wasn't the script kiddies who did that JPEG thing. It was a demo to show how _easily_ one could trick a user into double-clicking a file he or she doesn't know. Most Mac users have _no_ idea about these things, mainly because there never _were_ any real security threats on Mac OS X. And as such a demo, cloaking the file as a JPG was the right thing to do in my opinion.

There's no need to gloat now, either, I think. Sure: These holes have been filled. (Have they? Or will heise.de release a news blurb tomorrow about how this only fixes half of it?) But the past few weeks have clearly shown that if there _is_ enough energy in the world of script-kiddies etc., the Mac platform _could_ be targetted from time to time. And I think the more we gloat, the more envious people might become and start doing _just_ what you urged them to: To attack us with the real stuff. And we _don't_ want that. In my opinion.
__________________
macnews.net.tc is active again.
iMac 24" 2.4 GHz, 4 GB RAM, 320 GB HD. Mac OS X 10.5.6
MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.5.6
iPhone 3G 16 GB white, AppleTV 1G 40 GB

Mac user since 1987, Apple Product Professional 2007, 2008. Apple Certified Support Professional 10.5
Reply With Quote
  #4  
Old March 1st, 2006, 06:38 PM
ElDiabloConCaca's Avatar
U.S.D.A. Prime
 
Join Date: Aug 2001
Location: San Antonio, Texas
Posts: 10,672
Thanks: 3
Thanked 160 Times in 148 Posts
ElDiabloConCaca is a jewel in the roughElDiabloConCaca is a jewel in the roughElDiabloConCaca is a jewel in the rough
Did y'all even read the link?

Quote:
CVE-ID: CVE-2006-0394

Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Viewing a malicious web site may result in arbitrary code execution

Description: It is possible to construct a file which appears to be a safe file type, such as an image or movie, but is actually an application. When the "Open `safe' files after downloading" option is enabled in Safari's General preferences, visiting a malicious web site may result in the automatic download and execution of such a file. A proof-of-concept has been detected on public web sites that demonstrates the automatic execution of shell scripts. This update addresses the issue by performing additional download validation so that the user is warned (in Mac OS X v10.4.5) or the download is not automatically opened (in Mac OS X v10.3.9).
__________________
Power Macintosh G4/500MHz "Yikes!" 10.4.11 Server • 1024MB • 3 x 120GB + 320GB • DVR-111D
MacBook 2.0GHz Core 2 Duo - White 10.5.6 • 2048MB • 80GB • CD-RW/DVD-ROM
iPhone 3G 8GB • iPod Photo 60GB • iPod nano 1GB • AT&T DSL 6Mb/768k
http://www.jeffhoppe.com
Reply With Quote
  #5  
Old March 1st, 2006, 06:51 PM
fryke's Avatar
Super Moderator
 
Join Date: Sep 2000
Location: macosx.com
Posts: 13,498
Thanks: 2
Thanked 32 Times in 30 Posts
fryke has a spectacular aura aboutfryke has a spectacular aura about
Erh... Yes?
__________________
macnews.net.tc is active again.
iMac 24" 2.4 GHz, 4 GB RAM, 320 GB HD. Mac OS X 10.5.6
MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.5.6
iPhone 3G 16 GB white, AppleTV 1G 40 GB

Mac user since 1987, Apple Product Professional 2007, 2008. Apple Certified Support Professional 10.5
Reply With Quote
  #6  
Old March 1st, 2006, 07:58 PM
scruffy's Avatar
Notorious Olive Counter
 
Join Date: Dec 2000
Location: Soviet Canuckistan
Posts: 1,726
Thanks: 0
Thanked 0 Times in 0 Posts
scruffy is on a distinguished road
Have a look over the full description of the security update. Look at the CVE numbers - notice how many of them are from 2005? Throw the CVE ID into google, and you can find out more.

Just for example, the PHP vulnerabilities are from October to November 2005. That's a 3-4 month window of vulnerability. Every other OS vendor out there had patches out in a matter of days, but Apple took months. That is just plain unacceptable.
__________________

What is the robbing of a bank compared to the founding of a bank?
-- Bertold Brecht
Reply With Quote
  #7  
Old March 1st, 2006, 08:09 PM
JetwingX's Avatar
iWork for Apple <3
 
Join Date: Apr 2002
Location: Northern California
Posts: 1,780
Thanks: 0
Thanked 0 Times in 0 Posts
JetwingX is on a distinguished road
iChat. A malicious application named Leap.A that attempts to propagate using iChat has been detected. With this update for Mac OS X v10.4.5 and Mac OS X Server v10.4.5, iChat now uses Download Validation to warn of unknown or unsafe file types during file transfers.
Reply With Quote
  #8  
Old March 3rd, 2006, 12:30 PM
easterhay's Avatar
little green rosetta
 
Join Date: Nov 2005
Location: patagonia
Posts: 156
Thanks: 0
Thanked 0 Times in 0 Posts
easterhay is on a distinguished road
Switcher question here: Isn't the solution just for me to disable the "Open `safe' files after downloading" option in my prefs? That's what I've done, anyway.
And I agree with Fryke - it's one thing to taunt your Windozer mates down the pub about all the malware they keep getting clobbered with, another altogether to lay down the gauntlet to the script-bunnies. I for one am still luxuriating in the newfound security and peace of OsX. I'd prefer to carry on a while longer if possible.
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Perl: How do I "Require" or "Include" another perl script file? Jasoco Software Programming & Web Scripting 10 June 30th, 2008 05:05 PM
Entourage 2004 "From" addresses nickikene Mac OS X System & Mac Software 1 March 15th, 2005 10:40 AM
Attn: 17" Pbook Owners, 17" vs. 12" Heat Issue skidaniel Apple News, Rumors & Discussion 7 June 1st, 2003 12:07 AM
Preparing Apache for "Security Update July 2002"? TommyWillB Mac OS X System & Mac Software 0 June 29th, 2002 01:20 PM
"sudo" since Security Update from Apple laguila Mac OS X System & Mac Software 4 November 28th, 2001 09:27 PM


All times are GMT -5. The time now is 03:39 PM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.